Impact
A double‑free condition exists in GIMP’s read_layer_block() function, which can be triggered by parsing a specially crafted PSP file. When the same memory buffer is freed twice, heap corruption occurs. This can lead the GIMP application to crash, causing a denial of service, or in some scenarios allow the attacker to redirect execution flow within the GIMP process, potentially enabling local arbitrary code execution.
Affected Systems
Red Hat Enterprise Linux 6, 7, 8, and 9 systems that install the GIMP package from the Red Hat repositories are affected. The vulnerability exists in all GIMP releases distributed by Red Hat that have not applied the latest security fix for the PSP parser, regardless of the specific GIMP version number.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity level. The EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a local user‑initiated action where an attacker persuades a user to open a malicious PSP file. Successful exploitation could either crash the GIMP application, resulting in a denial of service, or enable code execution confined to the GIMP process.
OpenCVE Enrichment